Method and apparatus for protecting against side channel attacks against personal identification numbers
Summary by NHIP
Secure PIN Management Method
The method manages personal identification numbers in a secure portable device by scrambling and comparing PINs using specific keys. Distinctive elements include storing a second scrambled PIN in an EEPROM field, marking it untested, and validating it by comparing a newly created scrambled version against a received one.
Claim Score by NHIP
Abstract
A method for private personal identification number (PIN) management includes receiving a first PIN, receiving a first key used to scramble a second PIN that has been validated, receiving a first scrambled PIN comprising the second PIN scrambled with the first key, scrambling the first PIN with the first key to create a second scrambled PIN and validating the first PIN based at least in part on whether the first scrambled PIN matches the second scrambled PIN.

Term
Term ended
Expired 8 July 2026, 0.2 years ago.
- Priority and filed
- Granted
- Expired
- Today
33 claims: 3 independent, 30 dependent
- 1Broadest claimClaim Score 44, average(NHIP)A method for private personal identification number (PIN) management in a secure portable device having (1) executable instructions stored therein and (2) a processor wherein execution of said executable instructions on said processor provides the method comprising:receiving, by said processor, a first PIN;receiving, by said processor, a first key;receiving, by said processor, a first scrambled PIN;creating, by said processor, a second scrambled PIN by scrambling said first PIN with a second key;storing, by said processor, said second scrambled PIN in a field in a memory of said secure portable device;marking, by said processor, a test field, in said memory, for said stored second scrambled PIN as untested;creating, by said processor, a third scrambled PIN by scrambling said first PIN with said first key;comparing, by said processor, said first scrambled PIN with said third scrambled PIN;and marking, by said processor, said test field for said stored second scrambled PIN based at least in part on said comparing said first scrambled PIN with said third scrambled PIN.
- 9A program storage device readable by a machine, embodying a program of instructions executable by a secure portable device to perform a method for private personal identification number (PIN) management wherein execution of said program of instructions by a processor on said secure portable device causes the secure portable device to perform the method comprising:receiving, by said processor, a first PIN;receiving, by said processor, a first key;receiving, by said processor, a first scrambled PIN;creating, by said processor, a second scrambled PIN by scrambling said first PIN with a second key;storing, by said processor, said second scrambled PIN in a field in a memory of said secure portable device;marking, by said processor, a test field, in said memory, for said stored second scrambled PIN as untested;creating, by said processor, a third scrambled PIN by scrambling said first PIN with said first key;comparing, by said processor, said first scrambled PIN with said third scrambled PIN;and marking, by said processor, said test field for said stored second scrambled PIN based at least in part on said comparing said first scrambled PIN with said third scrambled PIN.
- 17An apparatus for private personal identification number (PIN) management, the apparatus comprising:a memory for storing at least one key, at least one scrambled PIN, and at least one validity indication;a processor;and executable instructions stored on said apparatus, wherein execution of said executable instructions on said processor causes the processor to perform the method including: receiving, by said processor, a first PIN;receiving, by said processor, a first key;receiving, by said processor, a first scrambled PIN;creating by said processor, a second scrambled PIN by scrambling said first PIN with a second key;storing, by said processor, said second scrambled PIN in a field in memory of said secure portable device;marking, by said processor, a test field, in said memory, for said stored second scrambled PIN as untested;creating by said processor, a third scrambled PIN by scrambling said first PIN with said first key;comparing, by said processor, said first scrambled PIN with said third scrambled PIN;and marking, by said processor, said test field for said stored second scrambled PIN based at least in part on said comparing said first scrambled PIN with said third scrambled PIN.
Independent claims3
146 paragraphs in 6 sections, as filed
CROSS REFERENCE TO RELATED APPLICATIONS
p-0002This application is related to the following:
p-0003U.S. patent application Ser. No. 10/164,658, filed Jun. 5, 2002 in the name of Eduard de Jong, entitled “Method for Private Personal Identification Number Management”, commonly assigned herewith; and
p-0004U.S. patent application Ser. No. 10/164,490, filed Jun. 5, 2002 in the name of Eduard de Jong, entitled “Apparatus for Private Personal Identification Number Management”, commonly assigned herewith.
FIELD OF THE INVENTION
p-0005The present invention relates to the field of computer science. More particularly, the present invention relates to a method and apparatus for protecting against side channel attacks on personal identification numbers.
BACKGROUND OF THE INVENTION
p-0006The challenge of identifying or authenticating a person on a local computer, or on the other end of a communication session, or in the role of the sender of a message, is a recurring theme in e-business. A typical solution uses user authentication methods based at least in part on passwords or PINs (personal identification numbers). A password or PIN is a word or code used as a security measure against unauthorized access to data. Typically, a user obtains a PIN as part of an enrollment process with a service provider. In this enrollment process, the service provider assesses user-supplied information and decides whether to provide the service to the user. If the service provider decides to provide service, the service provider issues a PIN to the user.
p-0007After enrolling with the service provider, the user uses the PIN to obtain access to the service. The user interface in this case consists of a prompt for a PIN. The user is typically allowed a fixed number of unsuccessful PIN attempts before user access is blocked.
p-0008A PIN or password is typically the primary means by which an individual user indicates authorization based at least in part on an intelligent thought process performed by the user. The user must recall the PIN from the user's memory and enter the digits corresponding to the PIN to obtain access to a service. PINs are often difficult to remember, especially when a user uses more than one PIN to access different services. A user may create a written copy of the PIN or PINs in an attempt to remember them. However, such a practice degrades security because the paper containing the PIN or PINs can be stolen or forwarded freely. Thus, static PIN-based user authentication mechanisms alone provide a relatively low level of security.
p-0009An improved form of user authentication is made possible by using a smart card or a magnetic stripe card in conjunction with a PIN. This is sometimes referred to as “two-factor” user authentication, combining “what you have” (the physical card) with “what you know” (the password needed to use the card). Because both possession of the card and knowledge of the PIN are required, two-factor user authentication can provide a higher level of security than user authentication based at least in part on a PIN or on a card alone.
p-0010<figref idrefs="DRAWINGS">FIG. 1</figref> is a block diagram that illustrates a typical mechanism for PIN management using a magnetic stripe card. A service provider <b>150</b> maintains a centralized cardholder database <b>110</b> that includes a primary account number (PAN) and an associated PIN for each cardholder. A cryptographic algorithm is typically used to generate the PIN based at least in part on a cryptographic key <b>140</b>, the PAN <b>120</b> and possibly other data <b>135</b>. The PAN for a user <b>100</b> is written on a magnetic strip card <b>105</b> and the card <b>105</b> is provided to the user <b>100</b>. The user <b>100</b> gains access to the account associated with a card <b>105</b> by presenting the card <b>105</b> to a card reader or card acceptance device (CAD) <b>155</b> in communication with the centralized cardholder database <b>110</b> and by entering a PIN <b>145</b>. The CAD <b>155</b> may be implemented in a PC or as a standalone device. The centralized cardholder database <b>110</b> grants user <b>100</b> access to the account if the PAN on the card <b>105</b> matches a PAN <b>120</b> in the database <b>110</b> and if the PIN <b>145</b> entered by the user <b>100</b> matches the PIN <b>125</b> that is associated with the PAN <b>120</b> in the database <b>110</b>.
p-0011<figref idrefs="DRAWINGS">FIG. 2</figref> is a block diagram that illustrates a typical mechanism for personal identification number (PIN) management using a smart card. Unlike a magnetic strip card, a smart card may include a CPU (central processing unit). Such a smart card can process data such as a PIN locally on the card. This processing may include PIN verification. Once a user is authenticated to the card, the card can be used to obtain access to a service. As shown in <figref idrefs="DRAWINGS">FIG. 2</figref>, smart card <b>205</b> includes multiple vendor applications (<b>235</b>, <b>240</b>, <b>290</b>), each of which may use the same PIN to control access to a service. Smart card <b>205</b> also includes an applet <b>215</b> provided by the card issuer. The issuer applet <b>215</b> includes PIN comparator <b>220</b> that compares PIN <b>270</b> entered by a user <b>200</b> with a validated PIN <b>230</b>. Typically, PIN comparator <b>220</b> allows a fixed number of unsuccessful PIN tries before access is blocked. This is illustrated below with reference to <figref idrefs="DRAWINGS">FIG. 3</figref>. Once access is blocked, user <b>200</b> must present the card <b>205</b> to service provider <b>280</b>. Service provider <b>280</b> maintains information about the smart card <b>205</b> that allows the smart card <b>205</b> to be reset. In one solution, service provider <b>280</b> maintains a “super PIN” that allows the smart card <b>205</b> to be reset based at least in part on cryptographic protocols.
p-0012Turning now to <figref idrefs="DRAWINGS">FIG. 3</figref>, a flow diagram that illustrates a method for personal identification number (PIN) management is presented. At <b>300</b>, a PIN from a user is received. At <b>305</b>, a determination is made regarding whether a try counter has exceeded a maximum number of try attempts. If the maximum number of try attempts has been exceeded, the card is set to block at <b>310</b>. If the maximum number of try attempts has not been exceeded, the try counter is incremented at <b>315</b> and a determination regarding whether the user-entered PIN matches a validated PIN is made. If the user-entered PIN matches the stored PIN, access is allowed at <b>325</b>. If the user-entered PIN does not match the validated PIN, additional PIN tries are accepted beginning at <b>300</b>. This process continues until the maximum number of try attempts has been exceeded.
p-0013Unfortunately, maintaining a PIN in a centralized database <b>105</b> that is beyond user control makes PINs vulnerable to misuse by a service provider <b>150</b>. It also makes the PIN vulnerable to attack by rogue software running on the service provider's system.
p-0014Cryptographic devices such as smart cards use a secret key to process input information and/or to produce output information. Security protocol designs typically assume that input and output messages are available to attackers, but that other information about the keys is not available. However, side-channel attacks can be used to obtain secret keys and other information stored on a smart card. A side-channel attack employs methods that have little to do with the security concepts underlying a system. For example, encryption focuses on key size and symmetric or public, strong algorithms to protect against brute-force attacks. While these attacks need to be addressed, a cryptographic system can be attacked in other way, from a totally different direction, addressing not the concept but the implementation as well as other parts of the overall system. Looking over a person's shoulder while typing a message that is destined to be encrypted, is one trivial example.
p-0015Side-channel attacks against smart cards focus on the processing performed by the card, rather than on the normal communications interface with the smart card. The data analyzed in such attacks may include measurements of power consumption, electromagnetic radiation and processing time. Integrated circuits such as those found in smart cards are built out of individual transistors that act as voltage-controlled switches. Current flows across the transistor substrate when charge is applied to or removed from the gate. This current then delivers charge to the gates of other transistors, interconnect wires, and other circuit loads. The motion of electric charge consumes power and produces electromagnetic radiation, both of which are externally detectable. Therefore, individual transistors produce externally observable electrical behavior. Because microprocessor logic units exhibit regular transistor switching patterns, it is relatively easy to identify macro-characteristics (such as microprocessor activity) by detailed monitoring of power consumption.
p-0016In Simple Power Analysis (SPA) attacks, an attacker directly observes a system's power consumption. The amount of power consumed varies depending on the microprocessor instruction performed. At high magnification, individual instructions can be differentiated.
p-0017Differential Power Analysis (DPA) is a much more powerful side-channel attack than SPA, and is relatively difficult to prevent. While SPA attacks use primarily visual inspection to identify relevant power fluctuations, DPA attacks use statistical analysis and error correction techniques to extract information correlated to secret keys.
p-0018Implementation of a DPA attack involves two phases: Data collection and data analysis. Data collection for DPA may be performed by detailed sampling of a device's power consumption during cryptographic operations as a function of time. Multiple cryptographic operations suspected of using the target key are observed. While the effects of a single transistor switching would be normally be impossible to identify from direct observations of a device's power consumption, the statistical operations used in DPA are able to reliably identify relatively small differences in power consumption.
p-0019An improvement is made possible by storing secret information such as PINs in encrypted form. However, the encrypted PIN must be decrypted before in order to compare the decrypted PIN with a user-entered PIN, thus making the decrypted PIN susceptible to side-channel attacks.
p-0020A device may be made less susceptible to side-channel attacks by reducing signal sizes, such as by using constant execution path code, choosing operations that leak less information in their power consumption and by physically shielding the device. Unfortunately, such signal size reduction generally cannot reduce the signal size to zero, as an attacker with a sufficiently large number of samples will still be able to perform side-channel attack analysis on the (heavily degraded) signal. Additionally, aggressive shielding can make attacks infeasible. However, such shielding adds significantly to a device's cost and size.
p-0021Introducing noise into power consumption measurements may also lessen side-channel attack susceptibility. This may be done by executing random code segments. Like signal size reductions, adding noise increases the number of samples required for an attack, possibly to an infeasibly large number. In addition, execution timing and order can be randomized. However, such modifications typically decrease execution efficiency and make the software code relatively complex, complicating code verification.
p-0022Smart cards are also susceptible to card tear. The term “card tear” refers to the removal of a smart card from a CAD before a transaction is complete. In one instance, a card is removed from a CAD before a user authentication transaction is complete (before the user has authenticated himself or herself to the card). In this case, the card is removed after a PIN has been entered but before the card has recorded the result of comparing the entered PIN with a valid PIN stored on the card. This technique typically prevents the card from becoming blocked, thus increasing the possible number of PIN comparison operations and increasing the amount of information susceptible to side channel attacks.
p-0023Accordingly, what is needed is a relatively secure user authentication solution that provides relatively limited access to an individual's PIN. Another need exists for such a solution that is relatively inexpensive. Yet a further need exists for such a solution that is relatively insensitive to side-channel attacks. Yet a further need exists for such a solution that is relatively efficient and verifiable.
SUMMARY OF THE INVENTION
p-0024A method for private personal identification number (PIN) management includes receiving a first PIN, receiving a first key used to scramble a second PIN that has been validated, receiving a first scrambled PIN comprising the second PIN scrambled with the first key, scrambling the first PIN with the first key to create a second scrambled PIN and validating the first PIN based at least in part on whether the first scrambled PIN matches the second scrambled PIN.
BRIEF DESCRIPTION OF THE DRAWINGS
p-0025The accompanying drawings, which are incorporated into and constitute a part of this specification, illustrate one or more embodiments of the present invention and, together with the detailed description, serve to explain the principles and implementations of the invention.
p-0026In the drawings:
p-0027<figref idrefs="DRAWINGS">FIG. 1</figref> is a block diagram that illustrates a typical mechanism for personal identification number (PIN) management using a magnetic stripe card.
p-0028<figref idrefs="DRAWINGS">FIG. 2</figref> is a block diagram that illustrates a typical mechanism for PIN management using a smart card.
p-0029<figref idrefs="DRAWINGS">FIG. 3</figref> is a flow diagram that illustrates a method for PIN management.
p-0030<figref idrefs="DRAWINGS">FIG. 4</figref> is a block diagram of a computer system suitable for implementing aspects of the present invention.
p-0031<figref idrefs="DRAWINGS">FIG. 5</figref> is a block diagram that illustrates an apparatus for private PIN management using exponential delay based at least in part on a stored exponent after failed PIN attempts in accordance with one embodiment of the present invention.
p-0032<figref idrefs="DRAWINGS">FIG. 6</figref> is a flow diagram that illustrates a method for private PIN management using exponential delay based at least in part on a stored exponent after failed PIN attempts in accordance with one embodiment of the present invention.
p-0033<figref idrefs="DRAWINGS">FIG. 7</figref> is a flow diagram that illustrates a method for private PIN management using exponential delay after failed PIN attempts in accordance with embodiments of the present invention.
p-0034<figref idrefs="DRAWINGS">FIG. 8</figref> is a flow diagram that illustrates a method for determining a PIN status in accordance with embodiments of the present invention.
p-0035<figref idrefs="DRAWINGS">FIG. 9</figref> is a flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention.
p-0036<figref idrefs="DRAWINGS">FIG. 10</figref> is a flow diagram that illustrates a method for testing a user-entered PIN against a validated PIN in accordance with one embodiment of the present invention.
p-0037<figref idrefs="DRAWINGS">FIG. 11</figref> is a flow diagram that illustrates a method for delaying after a failed PIN attempt in accordance with one embodiment of the present invention.
p-0038<figref idrefs="DRAWINGS">FIG. 12</figref> is a block diagram that illustrates an apparatus for private PIN management using exponential delay that protects against card tear in accordance with one embodiment of the present invention.
p-0039<figref idrefs="DRAWINGS">FIG. 13A</figref> is a block diagram that illustrates a data structure including an entry comprising two PIN attempts and corresponding PIN compare results in accordance with one embodiment of the present invention.
p-0040<figref idrefs="DRAWINGS">FIG. 13B</figref> is a block diagram that illustrates a data structure including an entry comprising two PIN attempts and a single PIN compare result in accordance with one embodiment of the present invention.
p-0041<figref idrefs="DRAWINGS">FIG. 14</figref> is a high-level flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention.
p-0042<figref idrefs="DRAWINGS">FIG. 15</figref> is a low-level flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention.
p-0043<figref idrefs="DRAWINGS">FIG. 16</figref> is a flow diagram that illustrates a method for checking a session identifier in accordance with one embodiment of the present invention.
p-0044<figref idrefs="DRAWINGS">FIG. 17</figref> is a flow diagram that illustrates a method for testing a user-entered PIN against a validated PIN in accordance with one embodiment of the present invention.
p-0045<figref idrefs="DRAWINGS">FIG. 18</figref> is a flow diagram that illustrates a method for recording a PIN compare attempt in accordance with one embodiment of the present invention.
p-0046<figref idrefs="DRAWINGS">FIG. 19</figref> is a flow diagram that illustrates a method for delaying after a failed PIN attempt in accordance with one embodiment of the present invention.
p-0047<figref idrefs="DRAWINGS">FIG. 20</figref> is a flow diagram that illustrates a method for recording a result in accordance with one embodiment of the present invention.
p-0048<figref idrefs="DRAWINGS">FIG. 21</figref> is a block diagram that illustrates an apparatus for private PIN management using scrambled PIN data in accordance with one embodiment of the present invention.
p-0049<figref idrefs="DRAWINGS">FIG. 22</figref> is a data flow diagram that illustrates using scrambled PIN data for private PIN management in accordance with one embodiment of the present invention.
p-0050<figref idrefs="DRAWINGS">FIG. 23</figref> is a flow diagram that illustrates a method for private PIN management using scrambled PIN data in accordance with one embodiment of the present invention.
p-0051<figref idrefs="DRAWINGS">FIG. 24</figref> is a flow diagram that illustrates a method for private PIN management using scrambled PIN data and a compare operation ordered to protect against side-channel attacks in accordance with one embodiment of the present invention.
p-0052<figref idrefs="DRAWINGS">FIG. 25</figref> is a block diagram that illustrates an apparatus for private PIN management using exponential delay that protects against card tear and side-channel attacks in accordance with one embodiment of the present invention.
p-0053<figref idrefs="DRAWINGS">FIG. 26</figref> is a low-level flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention.
p-0054<figref idrefs="DRAWINGS">FIG. 27</figref> is a flow diagram that illustrates a method for ascertaining a PIN test by checking a session identifier in accordance with one embodiment of the present invention.
p-0055<figref idrefs="DRAWINGS">FIG. 28</figref> is a flow diagram that illustrates a method for testing a user-entered PIN against a validated PIN in accordance with one embodiment of the present invention.
p-0056<figref idrefs="DRAWINGS">FIG. 29</figref> is a flow diagram that illustrates a method for recording a PIN compare attempt in accordance with one embodiment of the present invention.
p-0057<figref idrefs="DRAWINGS">FIG. 30</figref> is a high-level flow diagram that illustrates a method for delaying after a failed PIN attempt while also performing a PIN compare operation in accordance with one embodiment of the present invention.
p-0058<figref idrefs="DRAWINGS">FIG. 31</figref> is a flow diagram that illustrates a method scrambling entered PIN data in accordance with one embodiment of the present invention.
p-0059<figref idrefs="DRAWINGS">FIG. 32</figref> is a low-level flow diagram that illustrates a method for delaying in testing a PIN attempt while also performing a PIN compare operation in accordance with one embodiment of the present invention.
p-0060<figref idrefs="DRAWINGS">FIG. 33</figref> is a flow diagram that illustrates a method for performing a unit delay after a failed PIN attempt while also performing a PIN compare operation in accordance with one embodiment of the present invention.
p-0061<figref idrefs="DRAWINGS">FIG. 34</figref> is a flow diagram that illustrates a method for recording a result in accordance with one embodiment of the present invention.
DETAILED DESCRIPTION
p-0062Embodiments of the present invention are described herein in the context of a method and apparatus for protecting against side channel attacks on personal identification numbers. Those of ordinary skill in the art will realize that the following detailed description of the present invention is illustrative only and is not intended to be in any way limiting. Other embodiments of the present invention will readily suggest themselves to such skilled persons having the benefit of this disclosure. Reference will now be made in detail to implementations of the present invention as illustrated in the accompanying drawings. The same reference indicators will be used throughout the drawings and the following detailed description to refer to the same or like parts.
p-0063In the interest of clarity, not all of the routine features of the implementations described herein are shown and described. It will, of course, be appreciated that in the development of any such actual implementation, numerous implementation-specific decisions must be made in order to achieve the developer's specific goals, such as compliance with application- and business-related constraints, and that these specific goals will vary from one implementation to another and from one developer to another. Moreover, it will be appreciated that such a development effort might be complex and time-consuming, but would nevertheless be a routine undertaking of engineering for those of ordinary skill in the art having the benefit of this disclosure.
p-0064In the context of the present invention, the term “network” includes local area networks, wide area networks, the Internet, cable television systems, telephone systems, wireless telecommunications systems, fiber optic networks, ATM networks, frame relay networks, satellite communications systems, and the like. Such networks are well known in the art and consequently are not further described here.
p-0065In the context of the present invention, the term “randomized” describes the result of a random or pseudo-random number generation process. A “randomized process” describes the application of such a result to a process. Methods of generating random and pseudo-random numbers are known by those skilled in the relevant art.
p-0066In the context of the present invention, the term “session” or “user session” describes a period that begins when a user inserts a secure portable device such as a smart card or the like into a communications device such as a CAD, and ends when the secure portable device is removed from the communications device. A “session ID” is used to describe an identifier that uniquely identifies such a session.
p-0067In the context of the present invention, the term “impersistent mutable memory” describes a memory whose contents are both modifiable and affected by whether power is applied to the memory.
p-0068In the context of the present invention, the term “persistent mutable memory” describes a memory whose contents are both modifiable and unaffected by whether power is applied to the memory.
p-0069In the context of the present invention, the term “persistent immutable memory” describes a memory whose contents both unmodifiable and unaffected by whether power is applied to the memory. The term includes a persistent mutable memory that has been configured to function as a persistent immutable memory.
p-0070In accordance with one embodiment of the present invention, the components, processes and/or data structures may be implemented using C or C++ programs running on high performance computers (such as an Enterprise 2000™ server running Sun Solaris™ as its operating system. The Enterprise 2000™ server and Sun Solaris™ operating system are products available from Sun Microsystems, Inc. of Palo Alto, Calif.). Different implementations may be used and may include other types of operating systems, computing platforms, computer programs, firmware, computer languages and/or general-purpose machines. In addition, those of ordinary skill in the art will recognize that devices of a less general purpose nature, such as hardwired devices, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), or the like, may also be used without departing from the scope and spirit of the inventive concepts disclosed herein.
p-0071<figref idrefs="DRAWINGS">FIG. 4</figref> depicts a block diagram of a computer system <b>400</b> suitable for implementing aspects of the present invention. As shown in <figref idrefs="DRAWINGS">FIG. 4</figref>, computer system <b>400</b> includes a bus <b>402</b> which interconnects major subsystems such as a central processor <b>404</b>, a system memory <b>406</b> (typically RAM), an input/output (I/O) controller <b>408</b>, an external device such as a display screen <b>410</b> via display adapter <b>412</b>, serial ports <b>414</b> and <b>416</b>, a keyboard <b>418</b>, a fixed disk drive <b>420</b>, a floppy disk drive <b>422</b> operative to receive a floppy disk <b>424</b>, and a CD-ROM player <b>426</b> operative to receive a CD-ROM <b>428</b>. Many other devices can be connected, such as a pointing device <b>430</b> (e.g., a mouse) connected via serial port <b>414</b> and a modem <b>432</b> connected via serial port <b>416</b>. Modem <b>432</b> may provide a direct connection to a remote server via a telephone link or to the Internet via a POP (point of presence). Alternatively, a network interface adapter <b>434</b> may be used to interface to a local or wide area network using any network interface system known to those skilled in the art (e.g., Ethernet, xDSL, AppleTalk™).
p-0072Many other devices or subsystems (not shown) may be connected in a similar manner. Also, it is not necessary for all of the devices shown in <figref idrefs="DRAWINGS">FIG. 4</figref> to be present to practice the present invention, as discussed below. Furthermore, the devices and subsystems may be interconnected in different ways from that shown in <figref idrefs="DRAWINGS">FIG. 4</figref>. The operation of a computer system such as that shown in <figref idrefs="DRAWINGS">FIG. 4</figref> is readily known in the art and is not discussed in detail in this application, so as not to overcomplicate the present discussion. Code to implement the present invention may be operably disposed in system memory <b>406</b> or stored on storage media such as fixed disk <b>420</b>, floppy disk <b>424</b> or CD-ROM <b>428</b>.
p-0073<figref idrefs="DRAWINGS">FIGS. 5-34</figref> illustrate various embodiments of the present invention. <figref idrefs="DRAWINGS">FIGS. 7 and 8</figref> provide the basic context for embodiments of the present invention that use exponential delays after failed PIN attempts. <figref idrefs="DRAWINGS">FIGS. 5-11</figref> illustrate an apparatus and method for private PIN management using exponential delay based at least in part on a stored exponent after failed PIN attempts in accordance with embodiments of the present invention. <figref idrefs="DRAWINGS">FIGS. 7-8</figref> in conjunction with <figref idrefs="DRAWINGS">FIGS. 12-20</figref> illustrate an apparatus and method for private PIN management using exponential delay that protects against card tear in accordance with embodiments of the present invention. <figref idrefs="DRAWINGS">FIGS. 7-8</figref> in conjunction with <figref idrefs="DRAWINGS">FIGS. 25-34</figref> illustrate an apparatus and method for private PIN management using exponential delay that protects against card tear and side-channel attacks in accordance with embodiments of the present invention. <figref idrefs="DRAWINGS">FIGS. 21-24</figref> illustrate an apparatus and method for private PIN management using scrambled PIN data in accordance with embodiments of the present invention.
p-0074According to one embodiment of the present invention, a request for access to a service includes a PIN. The PIN is matched with a validated PIN. If the match is successful, access to the service is granted. If the match is unsuccessful, a delay period elapses before matching another PIN with the validated PIN. The delay period increases with successive unsuccessful matches. According to one embodiment of the present invention, the delay period increases exponentially with successive unsuccessful matches. According to another embodiment of the present invention, the delay period increases linearly with successive unsuccessful matches.
p-0075The above discussion regarding linear and exponential increases in the delay period is not intended to be limiting in any way. Those of ordinary skill in the art will recognize that any increasing function may be used.
p-0076Turning now to <figref idrefs="DRAWINGS">FIG. 5</figref>, a block diagram that illustrates an apparatus for private PIN management using exponential delay based at least in part on a stored exponent after failed PIN attempts in accordance with one embodiment of the present invention is presented. Secure portable device <b>500</b> may be any trusted portable device such as a mobile phone or a Java Card™ technology-enabled smart card, or the like. Java Card™ technology is described in Z. Chen, Java Card™ Technology for Smart Cards (2000). Secure portable device <b>500</b> includes a CPU <b>520</b>, a persistent mutable memory <b>505</b>, a non-persistent mutable memory <b>545</b> and a persistent immutable memory <b>515</b>. According to embodiments of the present invention, persistent mutable memory <b>505</b>, non-persistent mutable memory <b>545</b> and persistent immutable memory <b>515</b> comprise an EEPROM (electrical erasable programmable read-only memory), a RAM (random access memory) and a ROM (read-only memory), respectively. Persistent mutable memory <b>505</b> comprises storage for an exponent value <b>525</b> that is incremented with each successive failed PIN comparison and reset after a successful PIN comparison. Exponent <b>525</b> also determines the time period to delay after each failed PIN comparison. Persistent mutable memory <b>505</b> also comprises storage for a validated PIN <b>550</b> whose value must be matched by a user-entered PIN before access to a PIN-protected service is granted. Alternatively, one or more of persistent mutable memory components <b>525</b> and <b>550</b> may comprise a pointer to an exponent or a validated PIN, respectively. Persistent immutable memory <b>515</b> comprises PIN comparator <b>540</b> having code that is executed by CPU <b>520</b> whenever a user requests access to a service accessed via the secure portable device <b>500</b>. Non-persistent mutable memory <b>545</b> comprises storage for a session PIN flag <b>530</b> and a PIN entered during the current session <b>535</b>.
p-0077Many other devices or subsystems (not shown) may be connected in a similar manner. Also, it is not necessary for all of the devices shown in <figref idrefs="DRAWINGS">FIG. 5</figref> to be present to practice embodiments of the present invention. Furthermore, the devices and subsystems may be interconnected in different ways from that shown in <figref idrefs="DRAWINGS">FIG. 5</figref>.
p-0078In operation, a user in possession of the secure portable device <b>500</b> requests access to a service. The requested service includes anything for which restricted access is desired. By way of example, a requested service may provide access to a range of Internet services via an Internet portal. CPU <b>520</b> executes PIN comparator <b>540</b> code that checks a session PIN flag <b>530</b> that indicates whether a validated PIN has been entered for the current session. If a validated PIN has not been entered for the current session, and if the service is protected by a PIN, PIN comparator <b>540</b> compares a PIN entered in the current session <b>535</b> with a validated PIN <b>550</b>. If the PIN <b>535</b> and the validated PIN <b>550</b> match, access to the service is granted. If the PIN <b>535</b> and the validated PIN <b>550</b> do not match, PIN comparator <b>540</b> denies access, increments an exponent <b>525</b> and executes a delay for a time period based at least in part on the exponent <b>525</b>. Exponent <b>525</b> continues to be incremented with each successive failed PIN attempt, causing an exponential increase in the delay. Once the current PIN <b>535</b> matches the validated PIN <b>550</b>, session PIN flag <b>530</b> is set to indicate a validated PIN has been entered for the current session, the stored exponent <b>525</b> is set to indicate a successful PIN comparison and access to the service is granted.
p-0079According to one embodiment of the present invention, secure portable device <b>500</b> comprises a smart card.
p-0080According to another embodiment of the present invention, secure portable device <b>500</b> comprises a Java Card™ technology-enabled smart card.
p-0081According to one embodiment of the present invention, secure portable device <b>300</b> comprises a CDMA technology-enabled smart card. CDMA technology-enabled smart cards are described in CDMA Development Group Document #43, entitled “Smart Card Stage I Description”, Version 1.1, May 22, 1996, available at www.cdg.org.
p-0082According to another embodiment of the present invention, secure portable device <b>300</b> comprises a SIM (Subscriber Identity Module card) card. The term “SIM card” describes the smart card used in GSM (Global System for Mobile Communications) mobile telephones. The SIM includes the subscriber's personal cryptographic identity key and other information such as the current location of the phone and an address book of frequently called numbers. The SIM is described in “GSM 11.11 —Digital cellular telecommunications system (Phase 2+); Specification of the Subscriber Identity Module-Mobile Equipment (SIM-ME) interface (GSM 11.11)”, available at www.etsi.org.
p-0083According to another embodiment of the present invention, secure portable device <b>300</b> comprises a WIM (Wireless Interface Module). A WIM is a smart card in a WAP (Wireless Application Protocol) phone. It is described in “Wireless Identity Module Specification, available at www.wapforum.org.
p-0084According to another embodiment of the present invention, secure portable device <b>300</b> comprises a USIM (Universal Subscriber Identity Module). A USIM is a smart card for a 3GPP (3<sup>rd </sup>Generation Partnership Project) mobile phone. It is described in 3G TS 21.111 Version 4.0.0, USIM and IC Card Requirements, available at www.3gpp.org.
p-0085According to another embodiment of the present invention, secure portable device <b>300</b> comprises a UIM (User Identity Module). A UIM is a smart card for a 3GPP Project 2 (3GPP2) mobile phone. The term “R-UIM” is used when the smart card is removable. A UIM is a super set of the SIM and allows CDMA (Code Division Multiple Access)-based cellular subscribers to roam across geographic and device boundaries. The R-UIM is described in a specification issued by the 3rd Generation Partnership Project 2 (3GPP2) and entitled “Removable User Identity Module (R-UIM) for cdma2000 Spread Spectrum Systems (3GPP2 C.S0023-0)”, Jun. 9, 2000, available at http:/3gpp2.org.
p-0086The above description regarding various mobile phone technologies is not intended to be limiting in any way. Those of ordinary skill in the art will recognize that other secure portable devices may be used.
p-0087Turning now to <figref idrefs="DRAWINGS">FIG. 6</figref>, a flow diagram that illustrates a method for private PIN management using exponential delay based at least in part on a stored exponent after failed PIN attempts in accordance with one embodiment of the present invention is presented. At <b>600</b>, a delay exponent is initialized to 0. At <b>605</b>, a determination is made regarding whether a delay is pending. If a delay is pending, a new delay period is initiated at <b>610</b> and processing continues at <b>605</b>. The new delay period is based at least in part on the current exponent value. If no delay is pending, a PIN entered by a user is received at <b>615</b>. At <b>620</b>, a determination is made regarding whether the PIN matches a validated PIN. If the PIN does not match the validated PIN, the delay exponent is incremented at <b>625</b> and a new delay period is initiated at <b>610</b>. If the PIN matches the validated PIN, the delay exponent is reset to 0 at <b>630</b> and access to a PIN-protected resource is allowed at <b>635</b>. According to one embodiment of the present invention, processing is delayed for a time period based at least in part on the exponent before receiving another PIN from a user at <b>615</b> when the PIN does not match the validated PIN. According to another embodiment of the present invention, processing is delayed for a period of time based at least in part on the exponent before determining whether another user-entered PIN matches the validated PIN at <b>620</b> if the PIN does not match the validated PIN.
p-0088Turning now to <figref idrefs="DRAWINGS">FIG. 7</figref>, a flow diagram that illustrates a method for private PIN management using exponential delay after failed PIN attempts in accordance with embodiments of the present invention is presented. At <b>700</b>, an access request is received. The access request may include a PIN used to request access to a service. Alternatively, a user may be prompted for a PIN if the service is PIN-protected. At <b>705</b>, a determination is made regarding whether access to the service is PIN-protected. If the service is not PIN-protected, access is allowed at <b>720</b>. If the service is PIN-protected, the PIN status is determined at <b>710</b>. If the PIN status is acceptable, access to the service is allowed at <b>720</b>.
p-0089Turning now to <figref idrefs="DRAWINGS">FIG. 8</figref>, a flow diagram that illustrates a method for determining a PIN status in accordance with embodiments of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 8</figref> provides more detail for reference numeral <b>710</b> of <figref idrefs="DRAWINGS">FIG. 7</figref>. At <b>800</b>, a PIN test result is ascertained. A PIN test result may be set by a previous PIN status determination. At <b>805</b>, a determination is made regarding whether the result indicates a successful PIN test. If the result indicates a successful PIN test, a successful PIN status is indicated at <b>825</b>. If the result indicates an unsuccessful PIN test, at <b>810</b> a user-entered PIN is tested against a validated PIN. At <b>815</b>, the PIN test result is ascertained a second time. If the result indicates a successful PIN test, a successful status is indicated at <b>825</b>. If the result indicates an unsuccessful PIN test, a failure status is indicated at <b>830</b>.
p-0090Turning now to <figref idrefs="DRAWINGS">FIG. 9</figref>, a flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 9</figref> provides more detail for reference numerals <b>800</b> and <b>815</b> of <figref idrefs="DRAWINGS">FIG. 8</figref>. At <b>900</b>, a determination is made regarding whether a session PIN flag indicates success. The PIN test result flag is set at <b>905</b> and <b>910</b> based at least in part on the session PIN flag. According to one embodiment of the present invention, the session PIN flag is stored in a non-persistent mutable memory such as a RAM. Storage of the session PIN flag in such a memory ensures that the flag is reset automatically whenever power is applied. Thus, if a PIN check succeeds, the session PIN flag will indicate success while a smart card is in a communications device such as a CAD or the like. Reinserting a smart card will cycle power to the card, resetting the session PIN flag, causing the PIN test result to indicate a failure and thus requiring the user to enter a PIN once again.
p-0091Turning now to <figref idrefs="DRAWINGS">FIG. 10</figref>, a flow diagram that illustrates a method for testing a user-entered PIN against a validated PIN in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 10</figref> provides more detail for reference numeral <b>810</b> of <figref idrefs="DRAWINGS">FIG. 8</figref>. At <b>1000</b>, a PIN entered by a user is received. The PIN may have been included in the access request. If the PIN was not included with the access request, the secure portable device may prompt for a user-entered PIN. At <b>1005</b>, a determination is made regarding whether the user-entered PIN matches a validated PIN. If the received PIN matches the validated PIN, the session PIN flag is marked in non-persistent mutable memory at <b>1020</b> and the value “0” is stored in an exponent variable in persistent mutable memory at <b>1025</b>. Writing the value “0” for the exponent variable indicates the last PIN comparison was successful. According to one embodiment of the present invention, the persistent mutable memory comprises an EEPROM. If the user-entered PIN does not match the validated PIN, the stored exponent is incremented at <b>1010</b> and PIN processing is delayed at <b>1015</b>. The time of the delay is based at least in part on the value of the exponent.
p-0092Turning now to <figref idrefs="DRAWINGS">FIG. 11</figref>, a flow diagram that illustrates a method for delaying after a failed PIN attempt in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 11</figref> provides more detail for reference numeral <b>1015</b> of <figref idrefs="DRAWINGS">FIG. 10</figref>. At <b>1100</b>, a counter is initialized to 1. At <b>1105</b>, the counter is left-shifted based at least in part on the value of the exponent. Upon each left-shift operation, the least significant bit of the counter is populated with the value “0”, resulting in a counter value equal to 2<sup>(x−1)</sup>, where “x” is the exponent value. At <b>1110</b>, a determination is made regarding whether the counter equals 0. If the counter equals 0, the delay has been completed. If the counter does not equal 0, a unit delay is performed at <b>1115</b>. According to one embodiment of the present invention, performing a unit delay comprises executing a sequence of instructions selected based at least in part on the time required to execute the sequence of instructions. At <b>1120</b>, the counter is decremented and processing continues at <b>1110</b>. This process continues until the counter equals 0.
p-0093According to another embodiment of the present invention, upon each left-shift operation, the least-significant bit of the counter is populated with the value “1”, resulting in a counter value equal to 2<sup>x</sup>−1, where “x” is the exponent value.
p-0094<figref idrefs="DRAWINGS">FIGS. 12-21</figref> illustrate an apparatus and method for private PIN management using exponential delay that protects against card tear in accordance with embodiments of the present invention. A circular buffer is used to record both PIN attempts and the corresponding results of the PIN attempts. A PIN attempt is recorded before the comparison is performed. The recorded information includes at least an exponent that is used to determine a time period to delay after an unsuccessful PIN attempt. The algorithm ensures that a delay cannot be circumvented by physically removing a secure portable device such as a smart card from a communications device such as a CAD or the like before the PIN comparison and possible ensuing delay has been completed.
p-0095Turning now to <figref idrefs="DRAWINGS">FIG. 12</figref>, a block diagram that illustrates an apparatus for private PIN management using exponential delay that protects against card tear in accordance with one embodiment of the present invention is presented. Secure portable device <b>1200</b> may be any trusted portable device such as a mobile phone or a Java Card™ technology-enabled smart card, or the like. Secure portable device <b>1200</b> includes a CPU <b>1220</b>, a persistent mutable memory <b>1205</b>, a non-persistent mutable memory <b>1210</b> and a persistent immutable memory <b>1215</b>. According to embodiments of the present invention, persistent mutable memory <b>1205</b>, non-persistent mutable memory <b>1210</b> and persistent immutable memory <b>1215</b> comprise an EEPROM, a RAM and a ROM, respectively. Persistent mutable memory <b>1205</b> comprises storage for a buffer <b>1265</b> that includes two or more entries. Each entry comprises an entry number <b>1225</b>, a PIN <b>1230</b>, an exponent <b>1235</b> and an attempt reference ID <b>1240</b>. Alternatively, one or more of entry components <b>1225</b>, <b>1230</b>, <b>1235</b> and <b>1240</b> may comprise a pointer to an entry number, PIN, exponent or attempt reference ID, respectively.
p-0096Still referring to <figref idrefs="DRAWINGS">FIG. 12</figref>, the entry number <b>1225</b> indicates when the corresponding entry was stored relative to other entries in the buffer <b>1265</b>. By way of example, if increasing entry numbers are used, a first entry having an entry number that is lower than a second entry number indicates the second entry was stored after the first entry. The exponent <b>1235</b> comprises a number that is used to determine a time period to delay before checking another user-entered PIN after a failed PIN attempt. Exponent <b>1235</b> is incremented with each successive failed PIN comparison and reset after a successful PIN comparison. Attempt reference ID <b>1240</b> comprises an identifier that refers to the session associated with the entry. Persistent immutable memory <b>1215</b> comprises PIN comparator <b>1260</b> having code that is executed by CPU <b>1220</b> whenever a user requests access to a service accessed via the secure portable device <b>1200</b>. Non-persistent mutable memory <b>1210</b> comprises storage for a session PIN flag <b>1245</b>, a current attempt reference ID <b>1250</b> and a PIN entered during the current session <b>1255</b>.
p-0097Many other devices or subsystems (not shown) may be connected in a similar manner. Also, it is not necessary for all of the devices shown in <figref idrefs="DRAWINGS">FIG. 12</figref> to be present to practice embodiments of the present invention. Furthermore, the devices and subsystems may be interconnected in different ways from that shown in <figref idrefs="DRAWINGS">FIG. 12</figref>. Additionally, many data structures such as a record structure or the like may be used to represent an entry in embodiments of the present invention.
p-0098In operation, a user in possession of the secure portable device <b>1200</b> requests access to a service. The requested service includes anything for which restricted access is desired. By way of example, a requested service may provide access to a range of Internet services via an Internet portal. CPU <b>1220</b> executes PIN comparator <b>1260</b> code that checks a session PIN flag <b>1245</b> that indicates whether a validated PIN has been entered for the current session. If a validated PIN has not been entered for the current session, and if the service is protected by a PIN, PIN comparator <b>1260</b> indicates a PIN comparison attempt has begun by initializing a new buffer entry with the PIN value received from the user, incrementing the exponent of the new entry and storing the new entry. PIN comparator <b>1260</b> then compares a PIN entered in the current session <b>1255</b> with the PIN of the buffer entry that represents the last successful PIN attempt. If the two PINs match, access to the service is granted, the last buffer entry is copied to a new entry, the exponent of the new entry is set to 0 to indicate a successful match and the entry is stored. If the two PINs do not match, PIN comparator <b>1260</b> continues to delay for a time period based at least in part on the exponent of the new entry and records an unsuccessful PIN attempt by storing a new entry that is a copy of the last buffer entry. The exponent of buffer entries continues to be incremented with each successive failed PIN attempt, causing an exponential increase in the delay.
p-0099According to another embodiment of the present invention, each entry in buffer <b>1265</b> comprises an entry number <b>1225</b>, a PIN <b>1230</b> and an exponent <b>1235</b>, and the determination regarding whether a validated PIN has been entered for the current session is made by examining the session PIN flag <b>1245</b> in non-persistent mutable memory <b>1210</b>. Mapping the default value of the flag upon initialization to “False” ensures that a PIN comparison will be required for a new session.
p-0100According to embodiments of the present invention, secure portable device <b>1200</b> comprises a CDMA technology-enabled smart card, a SIM card, a WIM, a USIM, a UIM, a R-UIM or the like.
p-0101According to embodiments of the present invention, the exponent of an attempt entry is initialized to 1 at the beginning of a PIN comparison that follows a successful PIN comparison. After the PIN comparison, a corresponding result entry is created by copying the attempt entry and storing it in the buffer. If the PIN comparison was successful, the exponent value of the result entry is set to 0. If the PIN comparison was unsuccessful, the result entry is the same as the corresponding attempt entry. Thus, an exponent value of 0 in the last buffer entry indicates the last PIN comparison completed successfully. If the exponents of the last two buffer entries are the same, the last PIN comparison completed with a failed status. If the exponents of the last two buffer entries are not the same, a PIN comparison is in progress.
p-0102Turning now to <figref idrefs="DRAWINGS">FIG. 13A</figref>, a block diagram that illustrates a data structure including an entry comprising two PIN attempts and corresponding PIN compare results in accordance with one embodiment of the present invention is presented. Buffer <b>1300</b> includes buffer entries <b>1305</b>, <b>1310</b>, <b>1315</b> and <b>1320</b>. Buffer entry <b>1300</b> is initialized with a result entry comprising an exponent value of “0” and a validated PIN entered by a user (not shown in <figref idrefs="DRAWINGS">FIG. 13A</figref>). As shown in <figref idrefs="DRAWINGS">FIG. 13A</figref>, buffer entry <b>1305</b> was stored to mark the beginning of a first PIN comparison and buffer entry <b>1310</b> indicates the result of the first PIN comparison. Likewise, buffer entry <b>1315</b> was stored to mark the beginning of a second PIN comparison and buffer entry <b>1320</b> indicates the result of the second PIN comparison. If the exponent of buffer entry <b>1320</b> is 0, the PIN comparison was successful. If the exponent of buffer entry <b>1320</b> equals the exponent of buffer <b>1315</b>, the PIN comparison failed.
p-0103<figref idrefs="DRAWINGS">FIG. 13B</figref> is a block diagram that illustrates the same data structure as <figref idrefs="DRAWINGS">FIG. 13A</figref>, except only one of the PIN compare attempts has a corresponding PIN compare result. Buffer entry <b>1350</b> represents a case where a PIN compare attempt has not been completed. This is indicated when the exponent of the last buffer entry <b>1365</b> is nonzero and does not equal the exponent of the next-to-last buffer entry <b>1360</b>.
p-0104<figref idrefs="DRAWINGS">FIGS. 14 and 15</figref> are flow diagrams that illustrate a method for ascertaining a PIN test result in accordance with embodiments of the present invention. <figref idrefs="DRAWINGS">FIG. 14</figref> illustrates the process at a relatively high level of functionality. <figref idrefs="DRAWINGS">FIG. 15</figref> illustrates the same process using the data structures depicted in <figref idrefs="DRAWINGS">FIG. 12</figref>.
p-0105Turning now to <figref idrefs="DRAWINGS">FIG. 14</figref>, a high-level flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 14</figref> provides more detail for reference numerals <b>800</b> and <b>815</b> of <figref idrefs="DRAWINGS">FIG. 8</figref>. At <b>1400</b>, PIN data from the two latest entries in the buffer are obtained. At <b>1405</b>, a determination is made regarding whether the last buffer entry is valid. If the last buffer entry is valid, at <b>1410</b> a determination is made regarding whether the same entry is associated with the current session. If the entry is associated with the current session, a successful PIN test result is indicated at <b>1415</b>. If the last buffer entry is invalid, or if the last buffer entry is not associated with the current session, at <b>1420</b> a determination is made regarding whether a delay that resulted from a previous unsuccessful PIN attempt has been interrupted. If no delay has been interrupted, an unsuccessful PIN test result is indicated at <b>1430</b>. If a delay has been interrupted, the delay is repeated at <b>1425</b> and an unsuccessful PIN test result is indicated at <b>1430</b>.
p-0106Turning now to <figref idrefs="DRAWINGS">FIG. 15</figref>, a low-level flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 15</figref> provides more detail for reference numerals <b>800</b> and <b>815</b> of <figref idrefs="DRAWINGS">FIG. 8</figref>. At <b>1500</b>, the last buffer entry is located. At <b>1505</b>, the exponent field of the entry is read. At <b>1510</b>, the next-to-last buffer entry is located. At <b>1515</b>, the exponent field of the next-to-last buffer entry is read. At <b>1520</b>, a determination is made regarding whether the exponent of the last entry equals 0. If the exponent of the last entry equals 0, at <b>1525</b> the session ID of the last entry is checked to determine whether it is associated with the same session as the current session. If the exponent of the last entry does not equal 0, at <b>1530</b> a determination is made regarding whether the exponent of the next-to-last entry equals the exponent of the last entry. If the exponent of the next-to-last entry does not equal the exponent of the last entry, a delay is performed at <b>1535</b>. At <b>1540</b>, PIN test failure is indicated.
p-0107The order of the actions performed in <figref idrefs="DRAWINGS">FIG. 15</figref> is not intended to be limiting in any way. Those of ordinary skill in the art will recognize that order may be changed. By way of example, actions <b>1500</b> and <b>1505</b> may be performed after actions <b>1510</b> or <b>1515</b>. Additionally, action <b>1500</b> and <b>1510</b> may be performed before actions <b>1505</b> or <b>1515</b>.
p-0108Turning now to <figref idrefs="DRAWINGS">FIG. 16</figref>, a flow diagram that illustrates a method for checking a session identifier in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 16</figref> provides more detail for reference numeral <b>1525</b> of <figref idrefs="DRAWINGS">FIG. 15</figref>. At <b>1600</b>, the session ID from the last buffer entry is received. At <b>1605</b>, a determination is made regarding whether the received session ID matches the current session. At <b>1610</b> and <b>1615</b>, an indication of the PIN test result is made based at least in part on whether the received session ID matches the current session.
p-0109Turning now to <figref idrefs="DRAWINGS">FIG. 17</figref>, a flow diagram that illustrates a method for testing a user-entered PIN against a validated PIN in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 17</figref> provides more detail for reference numeral <b>810</b> of <figref idrefs="DRAWINGS">FIG. 8</figref>. At <b>1700</b>, PIN data entered by a user is received. The PIN may have been included in the access request. If the PIN was not included with the access request, the secure portable device may request a user-entered PIN. At <b>1705</b>, a PIN compare attempt is recorded by storing at least an exponent based at least in part on the last PIN test. At <b>1710</b>, a determination is made regarding whether the user-entered PIN matches a validated PIN, which may have been recorded previously as a successful PIN test. If the user-entered PIN does not match the validated PIN, a delay is performed at <b>1715</b>. At <b>1720</b>, the result of the delay is recorded in the buffer by storing at least an exponent value whose value depends upon whether the user-entered PIN matched the validated PIN.
p-0110Turning now to <figref idrefs="DRAWINGS">FIG. 18</figref>, a flow diagram that illustrates a method for recording a PIN compare attempt in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 18</figref> provides more detail for reference numeral <b>1705</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>. At <b>1800</b>, empty entries and the last entered entry in the buffer are determined. At <b>1805</b>, the exponent field of the last entered entry is read. At <b>1810</b>, a new entry is initialized with the user-entered PIN and the exponent of the last entered entry. At <b>1815</b>, the exponent field of the new field is incremented. At <b>1820</b>, a new entry is stored in an empty slot in the buffer. An entry replacement policy ensures that the entry having the validated PIN value is never overwritten. In determining empty slots in the buffer, the latest slot having an exponent value of 0 is never considered empty. If there is more than one entry having a non-zero exponent, the oldest entry is considered empty.
p-0111Turning now to <figref idrefs="DRAWINGS">FIG. 19</figref>, a flow diagram that illustrates a method for delaying after a failed PIN attempt in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 19</figref> provides more detail for reference numeral <b>1715</b> of <figref idrefs="DRAWINGS">FIG. 17</figref> and reference numeral <b>1535</b> of <figref idrefs="DRAWINGS">FIG. 15</figref>. At <b>1900</b>, a counter is initialized with 1. At <b>1905</b>, the exponent from the last buffer entry is received. At <b>1910</b>, the counter is left-shifted based at least in part on the exponent. At <b>1915</b>, a unit delay is performed. At <b>1920</b>, the counter is decremented. At <b>1925</b>, a determination is made regarding whether the counter equals 0. If the counter does not equal 0, another unit delay is performed at <b>1915</b>. This process continues until the counter equals 0.
p-0112Turning now to <figref idrefs="DRAWINGS">FIG. 20</figref>, a flow diagram that illustrates a method for recording a result in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 20</figref> provides more detail for reference numeral <b>1720</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>. At <b>2000</b>, the attempt entry stored prior to the delay is copied to a new entry. At <b>2005</b>, the exponent value of the new entry is set to 0 if the user-entered PIN equals the validated PIN. At <b>2010</b>, the new entry is stored.
p-0113<figref idrefs="DRAWINGS">FIGS. 21-24</figref> illustrates an apparatus and method for private PIN management using scrambled PIN data in accordance with embodiments of the present invention. A secure portable device such as a smart card or the like stores a scrambled version of a validated PIN and the key used to scramble the validated PIN. A user-entered PIN is validated by scrambling the user-entered PIN with the key and then comparing the scrambled user-entered PIN with the scrambled validated PIN. The user-entered PIN is then scrambled with a new key and this new scrambled PIN is used to validate a subsequent user-entered PIN. The new scrambled PIN may be created only if the result of the comparison is a match. Alternatively, the process may be made less sensitive to side-channel attacks by creating the new scrambled PIN before the PIN comparison and storing an entry that includes the new scrambled PIN and an indication that the new scrambled PIN is untested. The entry is then marked based at least in part on the result of the PIN comparison.
p-0114Turning now to <figref idrefs="DRAWINGS">FIG. 21</figref>, a block diagram that illustrates an apparatus for private PIN management using scrambled PIN data in accordance with one embodiment of the present invention is presented. Secure portable device <b>2100</b> may be any trusted portable device such as a mobile phone or a Java Card™ technology-enabled smart card, or the like. Secure portable device <b>2100</b> includes a CPU <b>2120</b>, a persistent mutable memory <b>2105</b>, a non-persistent mutable memory <b>2110</b> and a persistent immutable memory <b>2115</b>. According to embodiments of the present invention, persistent mutable memory <b>2105</b>, non-persistent mutable memory <b>2110</b> and persistent immutable memory <b>2115</b> comprise an EEPROM, a RAM and a ROM, respectively. Persistent mutable memory <b>2105</b> comprises storage for a buffer <b>2160</b> that includes two or more entries. Each entry comprises an entry number <b>2125</b>, a scrambled PIN <b>2130</b>, a key <b>2135</b> and an indication of whether the scrambled PIN <b>2130</b> has been tested <b>2140</b>. Alternatively, one or more of entry components <b>2125</b>, <b>2130</b>, <b>2135</b> and <b>2140</b> may comprise a pointer to an entry number, a scrambled PIN, a key or an indication of whether the scrambled PIN <b>2130</b> has been tested, respectively. The entry number <b>2125</b> indicates when the corresponding entry was stored relative to other entries in the buffer <b>2160</b>. The scrambled PIN <b>2130</b> comprises a PIN scrambled with the corresponding key <b>2135</b>.
p-0115Still referring to <figref idrefs="DRAWINGS">FIG. 21</figref>, persistent immutable memory <b>2115</b> comprises PIN comparator <b>2155</b> having code that is executed by CPU <b>2120</b> whenever a user requests access to a service accessed via the secure portable device <b>2100</b>. Non-persistent mutable memory <b>2110</b> comprises storage for a session PIN flag <b>2145</b> and a PIN entered during the current session <b>2150</b>.
p-0116Many other devices or subsystems (not shown) may be connected in a similar manner. Also, it is not necessary for all of the devices shown in <figref idrefs="DRAWINGS">FIG. 21</figref> to be present to practice embodiments of the present invention. Furthermore, the devices and subsystems may be interconnected in different ways from that shown in <figref idrefs="DRAWINGS">FIG. 21</figref>. Additionally, many data structures such as a record structure or the like may be used to represent an entry in embodiments of the present invention.
p-0117In operation, a user in possession of the secure portable device <b>2100</b> requests access to a service. The requested service includes anything for which restricted access is desired. By way of example, a requested service may provide access to a range of Internet services via an Internet portal. CPU <b>2120</b> executes PIN comparator <b>2155</b> code that checks a session PIN flag <b>2145</b> that indicates whether a validated PIN has been entered for the current session. If a validated PIN has not been entered for the current session, and if the service is protected by a PIN, PIN comparator <b>2155</b> indicates a PIN comparison attempt has begun by storing a new entry that includes the PIN entered by the user, scrambled with a new key. The new entry is marked to indicate it has not been validated. The entered PIN is also scrambled with a key found in the last validated entry and then compared with the scrambled PIN in the last validated entry. If there is a match, access to the service is granted, and the new entry is marked as being validated. If there is no match, the new entry is marked as having been tested but invalid.
p-0118According to embodiments of the present invention, secure portable device <b>2100</b> comprises a CDMA technology-enabled smart card, a SIM card, a WIM, a USIM, a UIM, a R-UIM or the like.
p-0119Turning now to <figref idrefs="DRAWINGS">FIG. 22</figref>, a data flow diagram that illustrates using scrambled PIN data for private PIN management in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 22</figref> illustrates validating three successive PINs: PIN 1 (<b>2200</b>), PIN 2 (<b>2202</b>) and PIN 3 (<b>2204</b>). Buffer <b>2206</b> is stored on a secure portable device and is initially populated with an entry <b>2208</b> that includes a first key <b>2210</b>, a first scrambled password <b>2212</b> that comprises a validated PIN scrambled with the first key <b>2210</b>, a result indicator <b>2214</b> that indicates a successful PIN comparison result, and an entry number <b>2216</b> identifying the entry as the first entry. A user in possession of the secure portable device enters (<b>2218</b>) a second PIN <b>2200</b> to access a service. If the service is PIN-protected, the latest valid entry <b>2208</b> is located (<b>2220</b>) and the secure portable device scrambles (<b>2222</b>) the second PIN <b>2200</b> with the first key <b>2210</b> to create a second scrambled PIN <b>2224</b>. The latest valid entry is the latest entry that includes a validated PIN. The second scrambled PIN <b>2224</b> is compared (<b>2226</b>) to the first scrambled PIN <b>2212</b>. If there is a match, access to a PIN-protected service is granted, and a third scrambled PIN <b>2228</b> is created by generating (<b>2230</b>) a second key <b>2232</b> and scrambling (<b>2234</b>) the second key <b>2214</b> with the second PIN <b>2200</b>. The second key <b>2232</b>, the third scrambled PIN <b>2228</b>, the result <b>2238</b> of the comparison (<b>2226</b>) and an entry number <b>2240</b> are stored in a new buffer entry <b>2242</b>.
p-0120Still referring to <figref idrefs="DRAWINGS">FIG. 22</figref>, when a third PIN <b>2202</b> is entered (<b>2244</b>), if the service is PIN-protected, the buffer <b>2206</b> is updated (<b>2296</b>), the latest valid entry <b>2242</b> is located (<b>2246</b>) and the secure portable device scrambles (<b>2248</b>) the third PIN <b>2202</b> with the second key <b>2236</b> to create a fourth scrambled PIN <b>2250</b>. The fourth scrambled PIN <b>2250</b> is compared (<b>2252</b>) to the third scrambled PIN <b>2228</b>. If there is a match, access to a PIN-protected service is granted, and a fifth scrambled PIN <b>2254</b> is created by generating (<b>2256</b>) a third key <b>2258</b> and scrambling (<b>2260</b>) the third key <b>2258</b> with the third PIN <b>2202</b>. The third key <b>2258</b>, the fifth scrambled PIN <b>2254</b>, the result <b>2264</b> of the comparison (<b>2252</b>) and an entry number <b>2266</b> are stored in a new buffer entry <b>2268</b>.
p-0121Still referring to <figref idrefs="DRAWINGS">FIG. 22</figref>, when a fourth PIN <b>2204</b> is entered (<b>2270</b>), if the service is PIN-protected, buffer <b>2206</b> is updated (<b>2298</b>), the latest valid entry <b>2268</b> is located (<b>2272</b>) and the secure portable device scrambles (<b>2274</b>) the fourth PIN <b>2204</b> with the fourth key <b>2262</b> to create a sixth scrambled PIN <b>2262</b>. The sixth scrambled PIN <b>2276</b> is compared (<b>2278</b>) to the fourth scrambled PIN <b>2254</b>. If there is a match, access to a PIN-protected service is granted, and a seventh scrambled PIN <b>2280</b> is created by generating (<b>2282</b>) a fourth key <b>2284</b> and scrambling (<b>2286</b>) the fourth key <b>2284</b> with the fourth PIN <b>2204</b>. The fourth key <b>2284</b>, the seventh scrambled password <b>2280</b>, the result <b>2264</b> of the comparison (<b>2278</b>) and an entry number <b>2292</b> are stored in a new buffer entry <b>2294</b>. This process continues with subsequent PINs, generating a new key and a new scrambled PIN with each successful PIN comparison.
p-0122<figref idrefs="DRAWINGS">FIGS. 23 and 24</figref> illustrate methods for private PIN management using scrambled PIN data in accordance with embodiments of the present invention. <figref idrefs="DRAWINGS">FIG. 23</figref> illustrates scrambling a PIN with a new key only if testing the PIN succeeds. <figref idrefs="DRAWINGS">FIG. 24</figref> illustrates scrambling a PIN with a new key before testing the PIN and indicating whether the scrambled PIN is valid based at least in part on the test.
p-0123Turning now to <figref idrefs="DRAWINGS">FIG. 23</figref>, a flow diagram that illustrates a method for private PIN management using scrambled PIN data in accordance with one embodiment of the present invention is presented. At <b>2300</b>, three items are received: (1) a first PIN, (2) a first key used to scramble a second PIN that has been validated, and (3) a first scrambled PIN that comprises the second PIN scrambled with the first key. At <b>2305</b>, the first PIN is scrambled with the first key to create a second scrambled PIN. At <b>2310</b>, the first scrambled PIN is compared with the second scrambled PIN. At <b>2315</b>, a determination is made regarding whether the scrambled PIN tries compared at <b>2310</b> match. If the scrambled PIN tries match, an indication that the first PIN is valid is made and access to a PIN-protected service is allowed.
p-0124Reference numerals <b>2320</b> and <b>2325</b> illustrate preparation for recording the PIN test result for use in validating a subsequent PIN. At <b>2325</b>, the first PIN is scrambled with a second key to create a third scrambled PIN. At <b>2325</b>, the third scrambled PIN is stored with the second key for use in validating a subsequent PIN.
p-0125As shown in <figref idrefs="DRAWINGS">FIG. 23</figref>, while a user may use the same PIN to access a service multiple times, the information used for PIN validation purposes changes frequently. This means that the comparison operations used during the PIN validation process compares different data, making the process relatively insensitive to a side-channel attack.
p-0126According to one embodiment of the present invention, the first key comprises a first session ID and the second key comprises a second session ID.
p-0127According to another embodiment of the present invention, the first key comprises a first randomized key and the second key comprises a second randomized key.
p-0128Turning now to <figref idrefs="DRAWINGS">FIG. 24</figref>, a flow diagram that illustrates a method for private PIN management using scrambled PIN data and a compare operation ordered to protect against side-channel attacks in accordance with one embodiment of the present invention is presented. At <b>2400</b>, three items are received: (1) a first PIN, (2) a first key used to scramble a second PIN that has been validated, and (3) a first scrambled PIN that comprises the second PIN scrambled with the first key. At <b>2405</b>, the first PIN is scrambled with a second key to create a second scrambled PIN. At <b>2410</b>, the second scrambled PIN is stored. At <b>2415</b>, the stored second scrambled PIN is marked as untested. At <b>2420</b>, the first PIN is scrambled with the first key to create a third scrambled PIN. At <b>2425</b>, the first scrambled PIN is compared with the third scrambled PIN. At <b>2430</b>, the stored second scrambled PIN is marked with the result of the comparison. At <b>2435</b>, a determination is made regarding whether the first scrambled PIN matches the third scrambled PIN. If the first scrambled PIN does not match the third scrambled PIN, an indication that the stored second scrambled PIN is invalid is made at <b>2440</b>. If the first scrambled PIN matches the third scrambled PIN, an indication that the stored second scrambled PIN is valid is made at <b>2445</b>.
p-0129Note that in <figref idrefs="DRAWINGS">FIG. 24</figref>, no determination is made until the PIN comparison result is received in persistent mutable memory. Because the execution paths for validating both a PIN that matches (reference numerals <b>2400</b>-<b>2430</b> and <b>2445</b>) and a PIN that does not match (reference numerals <b>2400</b>-<b>2430</b> and <b>2440</b>) are similar, the process illustrated in <figref idrefs="DRAWINGS">FIG. 24</figref> is relatively insensitive to side-channel attacks.
p-0130<figref idrefs="DRAWINGS">FIGS. 25-34</figref> illustrate an apparatus and method for private PIN management using exponential delay that protects against card tear and side-channel attacks in accordance with embodiments of the present invention. The apparatus and method includes the circular buffer aspect illustrated with respect to <figref idrefs="DRAWINGS">FIGS. 12-20</figref>. It also includes aspects that lessen side-channel attack susceptibility illustrated with respect to <figref idrefs="DRAWINGS">FIGS. 21-24</figref>.
p-0131Turning now to <figref idrefs="DRAWINGS">FIG. 25</figref>, a block diagram that illustrates an apparatus for private PIN management using exponential delay that protects against card tear and side-channel attacks in accordance with one embodiment of the present invention is presented. Secure portable device <b>2500</b> may be any trusted portable device such as a mobile phone or a Java Card™ technology-enabled smart card, or the like. Secure portable device <b>2500</b> includes a CPU <b>2520</b>, a persistent mutable memory <b>2505</b>, a non-persistent mutable memory <b>2510</b> and a persistent immutable memory <b>2515</b>. According to embodiments of the present invention, persistent mutable memory <b>2505</b>, non-persistent mutable memory <b>2510</b> and persistent immutable memory <b>2515</b> comprise an EEPROM, a RAM and a ROM, respectively. Persistent mutable memory <b>2505</b> comprises storage for a buffer <b>2565</b> that includes two or more entries. Each entry comprises an entry number <b>2525</b>, a scrambled PIN <b>2530</b>, an exponent <b>2535</b> and an attempt reference ID <b>2540</b>. Alternatively, one or more of entry components <b>2525</b>, <b>2530</b>, <b>2535</b> and <b>2540</b> may comprise a pointer to an entry number, a scrambled PIN, an exponent or an attempt reference ID, respectively. The entry number <b>2525</b> indicates when the corresponding entry was stored relative to other entries in the buffer <b>2555</b>. The scrambled PIN comprises a PIN scrambled with a key. The key may be a number such a number generated from a random or pseudo-random process. The key may also be a session ID or based at least in part on or derived from such a number. According to one embodiment of the present invention, the key comprises an attempt reference ID such as a session ID. The exponent <b>2535</b> comprises a number that is used to determine a time period to delay before checking another user-entered PIN after a failed PIN attempt. Exponent <b>2535</b> is incremented with each successive failed PIN comparison. Exponent <b>2535</b> is also reset after a successful PIN comparison. Attempt reference ID <b>2540</b> comprises an identifier such as a session ID that refers to the session associated with the entry.
p-0132Still referring to <figref idrefs="DRAWINGS">FIG. 25</figref>, persistent immutable memory <b>2515</b> comprises PIN comparator <b>2560</b> having code that is executed by CPU <b>2520</b> whenever a user requests access to a service accessed via the secure portable device <b>2500</b>. Non-persistent mutable memory <b>2510</b> comprises storage for a session PIN flag <b>2545</b>, a current attempt reference ID <b>2550</b> and a PIN entered during the current session <b>2555</b>.
p-0133Many other devices or subsystems (not shown) may be connected in a similar manner. Also, it is not necessary for all of the devices shown in <figref idrefs="DRAWINGS">FIG. 25</figref> to be present to practice embodiments of the present invention. Furthermore, the devices and subsystems may be interconnected in different ways from that shown in <figref idrefs="DRAWINGS">FIG. 25</figref>. Additionally, many data structures such as a record structure or the like may be used to represent an entry in embodiments of the present invention.
p-0134In operation, a user in possession of the secure portable device <b>2500</b> requests access to a service. The requested service includes anything for which restricted access is desired. By way of example, a requested service may provide access to a range of Internet services via an Internet portal. CPU <b>2520</b> executes PIN comparator <b>2560</b> code that checks a session PIN flag <b>2545</b> that indicates whether a validated PIN has been entered for the current session. If a validated PIN has not been entered for the current session, and if the service is protected by a PIN, PIN comparator <b>2560</b> indicates a PIN comparison attempt has begun by initializing a new buffer entry with a first PIN received from the user, scrambled with a key, incrementing the exponent of the new entry and storing the new entry. The new buffer entry also includes information used to derive the key used to scramble the first PIN, such as the current session ID.
p-0135PIN comparator <b>2560</b> then delays for a time period that is based at least in part on the exponent stored in the new buffer entry. A side effect of the delay is to compare (1) the first PIN scrambled with a second key used to scramble a second PIN that has been validated and (2) the second PIN scrambled with the second key. Another side effect of the delay is to terminate the delay if the two scrambled PINs match. If the two scrambled PINs match, access to the service is granted, the last buffer entry is copied to a new entry and the exponent of the new entry is set to 0 to indicate a successful match, and the entry is stored. If the two scrambled PINs do not match, PIN comparator <b>2560</b> continues to delay for a time period based at least in part on the exponent of the last entered buffer entry and records an unsuccessful PIN attempt by storing a new entry that is a copy of the last buffer entry. The exponent of buffer entries continues to be incremented with each successive failed PIN attempt, causing an exponential increase in the delay.
p-0136According to embodiments of the present invention, secure portable device <b>2500</b> comprises a CDMA technology-enabled smart card, a SIM card, a WIM, a USIM, a UIM a R-UIM or the like.
p-0137Turning now to <figref idrefs="DRAWINGS">FIG. 26</figref>, a low-level flow diagram that illustrates a method for ascertaining a PIN test result in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 26</figref> is similar to <figref idrefs="DRAWINGS">FIG. 15</figref> and provides more detail for reference numerals <b>800</b> and <b>815</b> of <figref idrefs="DRAWINGS">FIG. 8</figref>.
p-0138Turning now to <figref idrefs="DRAWINGS">FIG. 27</figref>, a flow diagram that illustrates a method for ascertaining a PIN test by checking a session identifier in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 27</figref> is similar to <figref idrefs="DRAWINGS">FIG. 16</figref> and provides more detail for reference numeral <b>2625</b> of <figref idrefs="DRAWINGS">FIG. 26</figref>.
p-0139Turning now to <figref idrefs="DRAWINGS">FIG. 28</figref>, a flow diagram that illustrates a method for testing a user-entered PIN against a validated PIN in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 28</figref> provides more detail for reference numeral <b>810</b> of <figref idrefs="DRAWINGS">FIG. 8</figref>. <figref idrefs="DRAWINGS">FIG. 28</figref> is similar to <figref idrefs="DRAWINGS">FIG. 17</figref> except that the PIN comparison is a part of the delay process (<b>2815</b>) in <figref idrefs="DRAWINGS">FIG. 28</figref>, whereas the PIN comparison (reference numeral <b>1710</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>) is separate from the delay process (reference numeral <b>1715</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>) in <figref idrefs="DRAWINGS">FIG. 17</figref>. Performing the PIN comparison as part of the delay process makes execution of code that tests a validated PIN similar to execution of code that tests an invalid PIN, thus making the code execution relatively insensitive to side-channel attacks.
p-0140Turning now to <figref idrefs="DRAWINGS">FIG. 29</figref>, a flow diagram that illustrates a method for recording a PIN compare attempt in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 29</figref> provides more detail for reference numeral <b>2805</b> of <figref idrefs="DRAWINGS">FIG. 28</figref>. <figref idrefs="DRAWINGS">FIG. 29</figref> is similar to <figref idrefs="DRAWINGS">FIG. 18</figref>, except that the PIN in <figref idrefs="DRAWINGS">FIG. 29</figref> is scrambled with a key that is based at least in part on data read from the last entered entry (<b>2915</b>) before the scrambled PIN is stored in a new entry in the buffer (<b>2930</b>), whereas <figref idrefs="DRAWINGS">FIG. 18</figref> illustrates storing unscrambled PIN data in a new buffer entry, making the PIN data stored according to <figref idrefs="DRAWINGS">FIG. 29</figref> relatively secure. According to one embodiment of the present invention, the key is based at least in part on a session ID read from the last entered entry.
p-0141Turning now to <figref idrefs="DRAWINGS">FIG. 30</figref>, a high-level flow diagram that illustrates a method for delaying after a failed PIN attempt while also performing a PIN compare operation in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 30</figref> provides more detail for reference numeral <b>2815</b> of <figref idrefs="DRAWINGS">FIG. 28</figref>. At <b>3000</b>, the latest entry with a validated PIN is located. At <b>3005</b>, PIN data from the located entry is loaded. At <b>3010</b>, the entered PIN data is scrambled. At <b>3015</b>, a delay based at least in part on the exponent of the last entry is performed. The PIN is scrambled (<b>3010</b>) before the compare (<b>3015</b>) because only the scrambled version of the second PIN and the session ID used to scramble it are available.
p-0142Turning now to <figref idrefs="DRAWINGS">FIG. 31</figref>, a flow diagram that illustrates a method scrambling entered PIN data in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 31</figref> provides more detail for reference numeral <b>3010</b> of <figref idrefs="DRAWINGS">FIG. 30</figref>. At <b>3100</b>, information to derive a key is obtained from the last entry in the buffer with a successful result. According to one embodiment of the present invention, the last entry in the buffer with a successful result includes an exponent value of 0. According to one embodiment of the present invention, the key is based at least in part on a session ID. At <b>3105</b>, the user-entered PIN data is scrambled with the key. According to one embodiment of the present invention, the “XOR” operation is applied to the user-entered PIN and the key.
p-0143Turning now to <figref idrefs="DRAWINGS">FIG. 32</figref>, a low-level flow diagram that illustrates a method for delaying in testing a PIN attempt while also performing a PIN compare operation in accordance with one embodiment of the present invention is presented. The delay is performed when the result of the PIN comparison is unsuccessful. <figref idrefs="DRAWINGS">FIG. 32</figref> provides more detail for reference numeral <b>3015</b> of <figref idrefs="DRAWINGS">FIG. 30</figref>. <figref idrefs="DRAWINGS">FIG. 32</figref> is similar to <figref idrefs="DRAWINGS">FIG. 19</figref> except that the unit delay of <figref idrefs="DRAWINGS">FIG. 32</figref> (<b>3215</b>) also performs a PIN comparison, making execution of the process illustrated by <figref idrefs="DRAWINGS">FIG. 32</figref> relatively insensitive to side-channel attacks. Additionally, at <b>3225</b>, the result of the matching operation performed as a side effect of the unit delay process (<b>3215</b>) is checked. Additional delays are performed based at least in part on the counter only if the match was unsuccessful. Thus, the delay process is short-circuited when the side effect of the delay indicates a match.
p-0144Turning now to <figref idrefs="DRAWINGS">FIG. 33</figref>, a flow diagram that illustrates a method for performing a unit delay after a failed PIN attempt while also performing a PIN compare operation in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 33</figref> provides more detail for reference numeral <b>3215</b> of <figref idrefs="DRAWINGS">FIG. 32</figref>. At <b>3300</b>, a result is initialized to 0. At <b>3305</b>, a counter is initialized to the length of the stored scrambled PIN data in bytes. At <b>3310</b>, a bit-wise exclusive “OR” operation is applied byte-by-byte to the result, the current PIN data and the last successful PIN data. A final result value of “0” indicates the current PIN data matches the last successful PIN data.
p-0145The above description regarding performing the exclusive “OR” operation is not intended to be limited in any way. Those of ordinary skill in the art will recognize that the operation may be applied two or more bytes at a time.
p-0146Turning now to <figref idrefs="DRAWINGS">FIG. 34</figref>, a flow diagram that illustrates a method for recording a result in accordance with one embodiment of the present invention is presented. <figref idrefs="DRAWINGS">FIG. 34</figref> provides more detail for reference numeral <b>2820</b> of <figref idrefs="DRAWINGS">FIG. 28</figref>. <figref idrefs="DRAWINGS">FIG. 34</figref> is similar to <figref idrefs="DRAWINGS">FIG. 20</figref>, except that the exponent value of the delay result entry is set based at least in part on the result of the exclusive “OR” operation (reference numeral <b>3310</b> of <figref idrefs="DRAWINGS">FIG. 33</figref>) performed as a side-effect of a delay process in <figref idrefs="DRAWINGS">FIG. 34</figref>, instead of being based at least in part on a direct comparison of two values outside of a delay process (reference numeral <b>1710</b> of <figref idrefs="DRAWINGS">FIG. 17</figref>) as in <figref idrefs="DRAWINGS">FIG. 20</figref>.
p-0147While embodiments and applications of this invention have been shown and described, it would be apparent to those skilled in the art having the benefit of this disclosure that many more modifications than mentioned above are possible without departing from the inventive concepts herein. The invention, therefore, is not to be restricted except in the spirit of the appended claims.
Contents6
35 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9740863B2 | Cited by | United States of America | Search report |
| US2011260749A1 | Cited by | United States of America | Pre-grant |
| US2002147918A1 | Cites | United States of America | Applicant |
| GB2347248A | Cites | United Kingdom | Applicant |
| US5495235A | Cites | United States of America | Applicant |
| US5699514A | Cites | United States of America | Applicant |
| US5721781A | Cites | United States of America | Applicant |
| US5742756A | Cites | United States of America | Applicant |
| US5781723A | Cites | United States of America | Applicant |
| US5826016A | Cites | United States of America | Applicant |
| US5841866A | Cites | United States of America | Applicant |
| US5930363A | Cites | United States of America | Applicant |
| US6009177A | Cites | United States of America | Search report |
| US6018583A | Cites | United States of America | Applicant |
| US6044154A | Cites | United States of America | Applicant |
| US6052690A | Cites | United States of America | Applicant |
| US6094656A | Cites | United States of America | Applicant |
| US6226744B1 | Cites | United States of America | Applicant |
| US6421768B1 | Cites | United States of America | Search report |
| US6438550B1 | Cites | United States of America | Applicant |
| US6460138B1 | Cites | United States of America | Search report |
| WO9745817A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 16466202 | United States of America | A | |
| US20020164662 | – | – | – |
87 transactions on the USPTO file
Allowed after 4 non-final rejections, 1 final rejection and 1 appeal.
- Non-final rejections
- 4
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | |
|---|---|
| Payment of Maintenance Fee, 12th Year, Large Entity | |
| Post Issue Communication - Certificate of Correction | |
| Recordation of Patent Grant Mailed | |
| Patent Issue Date Used in PTA CalculationAllowed | |
| Issue Notification MailedAllowed | |
| Dispatch to FDC | |
| Mail Response to 312 Amendment (PTO-271) | |
| Application Is Considered Ready for Issue | |
| Response to Amendment under Rule 312 | |
| Issue Fee Payment Verified | |
| Amendment after Notice of Allowance (Rule 312)Allowed | |
| Issue Fee Payment Verified | |
| Issue Fee Payment Received | |
| Printer Rush- No mailing | |
| Pubs Case Remand to TC | |
| Mail Examiner's Amendment | |
| Mail Notice of AllowanceAllowed | |
| Notice of Allowance Data Verification CompletedAllowed | |
| Examiner's Amendment Communication | |
| Appeal Brief Review Complete | |
| Date Forwarded to Examiner | |
| Appeal Brief Filed | |
| Notice of Appeal Filed | |
| Request for Extension of Time - Granted | |
| Mail Advisory Action (PTOL - 303) | |
| Advisory Action (PTOL-303) | |
| Date Forwarded to Examiner | |
| Response after Final Action | |
| Mail Final Rejection (PTOL - 326)Final rejection | |
| Case Docketed to Examiner in GAU | |
| Final RejectionFinal rejection | |
| Date Forwarded to Examiner | |
| Response after Non-Final Action | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Date Forwarded to Examiner | |
| Information Disclosure Statement considered | |
| Reference capture on IDS | |
| Information Disclosure Statement (IDS) Filed | |
| Response after Non-Final Action | |
| Information Disclosure Statement (IDS) Filed | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Date Forwarded to Examiner | |
| Response to Election / Restriction Filed | |
| Mail Restriction Requirement | |
| Restriction/Election Requirement | |
| Date Forwarded to Examiner | |
| New or Additional Drawing Filed | |
| Response after Non-Final Action | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Date Forwarded to Examiner | |
| Response after Non-Final Action | |
| Request for Extension of Time - Granted | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Correspondence Address Change | |
| Change in Power of Attorney (May Include Associate POA) | |
| Miscellaneous Incoming Letter | |
| Miscellaneous Incoming Letter | |
| Information Disclosure Statement considered | |
| Information Disclosure Statement (IDS) Filed | |
| Certified Translation of Foreign Priority Document | |
| IFW TSS Processing by Tech Center Complete | |
| Reference capture on IDS | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Oath or Declaration Filed (Including Supplemental) | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Case Docketed to Examiner in GAU | |
| Application Dispatched from OIPE | |
| Application Is Now Complete | |
| IFW Scan & PACR Auto Security Review | |
| Oath or Declaration Filed (Including Supplemental) | |
| Initial Exam Team nn |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Fee paymentFPAY | FPAY | |
| AssignmentAS | AS | |
| Fee paymentFPAY | FPAY | |
| Certificate of correctionCC | CC | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 7596531
- Publication, EPODOC
- US7596531
- Application
- 10164662
- Application, DOCDB
- 16466202
- Application, EPODOC
- US20020164662
Titles
- English
- Method and apparatus for protecting against side channel attacks against personal identification numbers
Patent term adjustment
- A delay
- +909 daysthe office missed an examination deadline
- B delay
- +668 dayspendency past three years
- Applicant delay
- −83 days
- Net adjustment
- 1,494 days
Classification
- CPC, 4
- G06F21/31
- G06Q20/4012
- G06Q30/018
- G06F21/755
- IPC, 1
- G06F21 00
- USPC, 5
- 705072000
- 705050000
- 705317000
- 713168000
- 713184000